CISA's list that day

21 August 2026

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Entra ID and Synacor Zimbra Collaboration Suite (ZCS). US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-73570OS Command InjectionSynacor Zimbra Collaboration Suite (ZCS)Patch nowForensic triage required by CISA0.72
CVE-2026-69836Deserialization of Untrusted DataMicrosoft Entra IDRemoved from CISA's list0.02

Other changes that day

  1. CVE-2012-0158 Microsoft MSCOMCTL.OCXRansomware use: Unknown to Known.
  2. CVE-2020-5135 SonicWall SonicOSRansomware use: Unknown to Known.
  3. CVE-2021-43226 Microsoft WindowsRansomware use: Unknown to Known.
  4. CVE-2026-69836 Microsoft Entra IDRemoved from CISA's list.